Infected With Pop Up

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by taiamdo, Mar 25, 2017.

  1. taiamdo

    taiamdo Private E-2

    Hi, I clicked on free porn movie and something was installed. Since then, pop-up appears every few minutes telling me I have been charged. How can I get rid of this annoiying ad? I did cc cleaner and malwrebyte quarantine but still pop up continues...
     
    Last edited by a moderator: Mar 25, 2017
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do not attach inline logs. If you need help, please follow the Read and Run First instructions.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the instructions and do not post inline logs.
     
  4. taiamdo

    taiamdo Private E-2

    Uploaded file as per instruction
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the attached file from:
    RogueKiller
    Hitman
    MBAM
    MGLogs
     
  6. taiamdo

    taiamdo Private E-2

    loading what I have so far..
     

    Attached Files:

  7. taiamdo

    taiamdo Private E-2

    For RogueKiller, after scan is finished the Roguekiller screen disappears and I have no option to export the scan result. Why is this?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you right click and run as Administrator?
     
  9. taiamdo

    taiamdo Private E-2

    yes I did. Can you proceed analysis w/o Rogue Killer?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this happen in all browsers?
     
  11. taiamdo

    taiamdo Private E-2

    not sure what you mean. I have Roguekiller.exe on my desktop, I just right click and run as admin.
     
  12. taiamdo

    taiamdo Private E-2

    is there any action i can take to get rid of the pop up at this point?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me what browser you are using when the pop-up appears.
     
  14. taiamdo

    taiamdo Private E-2

    Im using google chrome but pops up with other browsers too. Even when I dont open up any browser, it pops up every 2 mins or so.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :killallprocesses
    :files
    C:\Windows\Temp\
    C:\Users\NEC\AppData\Local\Temp\
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista ,Win7 or Win8, Win10, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. taiamdo

    taiamdo Private E-2

    I followed instructions but the pop up still appears...please help
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  18. taiamdo

    taiamdo Private E-2

    windows 2000 no longer supported...
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried using a restore point?
     
  20. taiamdo

    taiamdo Private E-2

    I am not aware of what restore point is, can you elaborate and advise how I can go about this?
     
  21. taiamdo

    taiamdo Private E-2

    Regarding rogue kill, I disabled windows defender and was able to get the log. attaching.
     

    Attached Files:

  22. taiamdo

    taiamdo Private E-2

    seems like rogue kill has fixed my issue after deleting all scanned result
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! glad you got RogueKiller to work!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds